Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in BC-BMT-WFM-WEB, SAP security note 2132282

SAP Note 2132282SAP Security NoteMedium priority

SAP security note 2132282, “Potential denial of service in BC-BMT-WFM-WEB”, is a program error note released on 24.08.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Business Management > Business Workflow > Web Integration (BC-BMT-WFM-WEB)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on24.08.2017
LanguageEnglish

Description

Symptom

An attacker can remotely exploit BC-BMT-WFM-WEB, rendering it, and potentially the resources that are used to serve BC-BMT-WFM-WEB, unavailable.

Solution

Implement the correction instructions.

The XML deserialization is protected by an additional function, which uses heuristics to mitigate any attacks. Under certain circumstances, the heuristics might be triggered even though there is no attack (false positive). As a result, you can deactivate this function in transaction SWPA (see attachment “parameter.docx”).

Reason and prerequisites

An attacker can cause a situation in which the process enters an endless loop that claims the entire available processing time. This causes the entire system to become unresponsive until the process is terminated manually. An attacker can use this flaw to launch a denial-of-service (DoS) attack.

References

Affected components

  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 711
  • SAP_BASIS 730
  • SAP_BASIS 731
  • SAP_BASIS 740

Full note on SAP: SAP Support Launchpad note 2132282

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More